CVE-2020-22987: Microstrategy Web SDK

Medium severity, CVSS 6.1. EPSS: 1.5% chance of exploitation in the next 30 days.

Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the fileToUpload parameter to the uploadFile task.

Affected products

Published 2022-05-12. Last modified 2026-07-09.